First published: Thu Jan 30 2025(Updated: )
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations for Logs |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-22219 is considered a high severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2025-22219, it is recommended to apply the latest security updates provided by VMware for Aria Operations for Logs.
CVE-2025-22219 affects users of VMware Aria Operations for Logs with non-administrative privileges.
An attacker exploiting CVE-2025-22219 can inject malicious scripts leading to unauthorized actions with administrative privileges.
CVE-2025-22219 was disclosed in January 2025 as part of a broader security advisory for VMware products.